Term Finance's $8.5M Exploit Wasn't a Hack. It Was Governance.
Term Finance's Meta Vaults are dead after an attacker used the protocol's own governance process to drain $8.5M. The exploit didn't break the code, it worked as designed. Here's how the opt-out veto system became the attack vector.
Term Finance permanently killed its Meta Vaults on Aug. 23 after an attacker routed roughly $8.5 million through the protocol's own governance process. The numbers: 2,843 ETH worth $6.87 million and 1.68 million USDC that got swapped for DAI.
This wasn't a smart contract exploit in the traditional sense. The code worked. That's the problem. The attacker didn't brute force anything. They just used the governance system the way it was built.
Term's Meta Vaults use an opt-out governance model. Here's the relevant design: vault token holders can veto queued parameter changes during a seven-day delay. If no one vetoes, the change executes. An ETH Meta Vault proposal sat open for six days. No veto. On execution, the first action set the cooldown delay to zero. That removed the second waiting period entirely.
Then 2,841.7435 WETH routed through a newly added strategy to an attacker-controlled address. The transaction hit at 06:25 UTC. Twenty-two minutes later a second transaction executed five proposals across five USDC vaults, removing 1,679,639.29 USDC.
So the whole attack relied on one thing: nobody paying attention for six days. That's not a technical failure. That's a governance failure.
Yearn was quick to distance itself. Term's vault contracts use Yearn V3 architecture, but the exploit moved through Term's custom governance wrapper. Yearn says standard Yearn vaults are unaffected. That's probably true. But it doesn't change what happened.
Term hasn't confirmed the $8.5 million total or published a vault-by-vault accounting. It also hasn't explained how the proposer obtained authority to queue those actions or why the veto and delay controls didn't stop them. Withdrawals are still open but Term won't commit to reimbursing depositors or provide a recovery timetable.
Here's my take: governance systems with opt-out vetoes trust token holders to show up. They don't. This attack wasn't clever. It was a test of whether anyone was watching. Nobody was. That's a hard lesson for every protocol shipping similar delay-based governance. Read the source. The docs are lying.
Explore More
Key Terms Explained
An approval term meaning authentic, bold, or worthy of respect.
The process of making decisions about a protocol's development and direction.
A set of rules governing how a network or application operates.
Self-executing code stored on a blockchain that runs when conditions are met.